Hi,
My computer has been getting infected by one virus after another. I believe it is still infected even though I've tried a number of programs. I have run (and still have some programs installed)
- Spybot
- AVG
- Malwarebytes' Anti-Malware
- Microsoft Security
- Comodo Cleaner
- Combofix
I have read that you do not recommend using cleaners and fix tools - I suppose I'm lucky that my computer didn't turn into a brick. I used combofix to remove the 'google redirect virus'. It detected rookit activity and appears to have fixed that problem.
I have also had the 'XP Antivirus 2010' virus, which was removed. My anti-virus also picked up win32/Alureon.H a day or so later.
THANKS for your help!
DDS logs:
DDS (Ver_10-03-17.01) - NTFSx86
Run by rhong at 22:15:46.43 on Mon 03/05/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.1023.411 [GMT 10:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Outdated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Siemens\Digsi4\Common\sws\almsrv\almsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\COMMON~1\Nokia\MPLATF~1\NOKIAM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\rhong\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = https://my.monash.edu.au/
uInternet Settings,ProxyServer = 10.84.243.71:8080
uInternet Settings,ProxyOverride = hxxp://amfm.ue.com.au;10.250.1.103;http://plp.ue.com.au;https://plp.ue.com.au;http://j2eprd01.ue.com.au;http://vtalpwinf01.alinta.net.int;http://vtalpwctx10;http://vtalpwctx60;<local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [NokiaOviSuite2] c:\program files\nokia\nokia ovi suite\NokiaOviSuite.exe -tray
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [WatchDog] c:\program files\intervideo\dvd check\DVDCheck.exe
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\PccNTMon.exe" -HideWindow
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [SqlEng] "c:\program files\sqlany50\win32\rtdsk50.exe" -n protest.db"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\rhong\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{871df2be-41d2-4334-ac33-839af16fc8fe}\Icon3E5562ED7.ico
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoStartMenuMyMusic = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
uPolicies-explorer: DisablePersonalDirChange = 1 (0x1)
uPolicies-system: ProfileQuotaMessage = Alinta Helpdesk: You have exceeded your profile storage space. Before you can log off, you need to move some items from your profile to your "My Documents" folder or your computer's "D:\Transient" folder.
uPolicies-system: MaxProfileSize = 30000 (0x7530)
uPolicies-system: WarnUserTimeout = 15 (0xf)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269862591171
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269862795015
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
DPF: {89FD2ED9-0000-0000-0000-000000000000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab53083.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab53852.cab
DPF: {DEA03428-0000-0000-0000-000000000000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-5-1 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-5-1 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-1 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-1 29512]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-1 242896]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R2 almservice;Automation License Server;c:\siemens\digsi4\common\sws\almsrv\almsrvx.exe [2006-9-16 573502]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-1 308064]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-5-1 2325816]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-5-1 5888008]
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\tmxpflt.sys [2005-2-18 197648]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2005-2-18 31248]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-5-1 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-5-1 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-5-1 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-5-1 26120]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2005-10-24 80384]
S0 CFRMD;CFRMD;c:\windows\system32\drivers\cfrmd.sys --> c:\windows\system32\drivers\CFRMD.sys [?]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-5-1 30104]
S3 TPM12;NSC Integrated Trusted Platform Module 1.2;c:\windows\system32\drivers\nsctpm12.sys [2006-2-24 13056]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
============== File Associations ===============
.scr=AutoCADLTScriptFile
=============== Created Last 30 ================
2010-05-03 11:30:24 0 d-----w- c:\docume~1\rhong\applic~1\AVG9
2010-05-01 11:33:54 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-01 11:33:53 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-01 11:33:52 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-01 11:33:46 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-01 11:33:37 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-01 11:33:19 0 d-----w- c:\windows\system32\drivers\Avg
2010-05-01 11:30:14 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-05-01 11:30:14 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-05-01 11:27:37 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-05-01 11:25:04 0 d-----w- c:\program files\AVG
2010-05-01 10:32:56 0 d-----w- c:\docume~1\rhong\applic~1\ComodoGroup
2010-05-01 10:24:59 0 d-----w- c:\documents and settings\rhong\Application DataComodoGroup
2010-05-01 10:10:46 0 d-----w- c:\program files\COMODO
2010-04-27 06:24:15 0 d-sha-r- C:\cmdcons
2010-04-27 06:10:19 77312 ----a-w- c:\windows\MBR.exe
2010-04-27 06:10:15 98816 ----a-w- c:\windows\sed.exe
2010-04-27 06:10:15 261632 ----a-w- c:\windows\PEV.exe
2010-04-27 06:10:15 161792 ----a-w- c:\windows\SWREG.exe
2010-04-27 06:09:49 0 d-----w- C:\ComboFix
2010-04-26 07:05:10 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-26 07:05:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-04-24 10:13:39 0 d-----w- c:\docume~1\rhong\applic~1\Malwarebytes
2010-04-24 10:12:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-24 10:12:38 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-24 10:12:36 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-24 10:12:35 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 02:51:04 0 d-----w- c:\windows\system32\XPSViewer
2010-04-08 02:48:42 14048 ------w- c:\windows\system32\spmsg2.dll
2010-04-08 02:28:23 0 d-----w- c:\docume~1\alluse~1\applic~1\Nokia
2010-04-08 02:20:32 0 d-----w- c:\docume~1\rhong\applic~1\Nokia Ovi Suite
2010-04-08 02:14:59 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-08 02:14:59 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2010-04-08 02:14:44 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-04-08 02:14:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-04-08 02:14:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-04-08 01:55:10 0 d-----w- c:\program files\common files\Nokia
2010-04-08 01:50:31 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-04-08 01:49:14 0 d-----w- c:\program files\PC Connectivity Solution
2010-04-08 01:48:38 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-04-08 01:48:38 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-04-08 01:48:36 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-04-08 01:48:32 18048 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-04-08 01:48:31 660480 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-04-08 01:48:31 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2010-04-08 01:48:01 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-04-07 14:41:39 0 d-----w- c:\program files\MSXML 6.0
2010-04-07 14:37:53 0 d-----w- c:\program files\Nokia
2010-04-07 14:37:53 0 d-----w- c:\docume~1\alluse~1\applic~1\OviInstallerCache
2010-04-05 08:32:28 3248 ----a-w- c:\windows\system32\wbem\Outlook_01cad49a864f46f8.mof
==================== Find3M ====================
2010-02-24 00:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
============= FINISH: 22:17:18.31 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 14/07/2006 3:43:25 AM
System Uptime: 5/03/2010 9:40:29 PM (1417 hours ago)
Motherboard: Hewlett-Packard | | 0934
Processor: Intel(R) Pentium(R) M processor 1.73GHz | U10 | 1729/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 20 GiB total, 2.411 GiB free.
D: is FIXED (NTFS) - 17 GiB total, 16.913 GiB free.
E: is CDROM ()
M: is NetworkDisk (*NT5CSC) - 20 GiB total, 2.411 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
Description: SMC IrCC - Fast Infrared Port
Device ID: ACPI\SMCF010\5&16574359&0
Manufacturer: SMC
Name: SMC IrCC - Fast Infrared Port
PNP Device ID: ACPI\SMCF010\5&16574359&0
Service: SMCIRDA
Class GUID:
Description:
Device ID: ACPI\IFX0101\4&3863886D&0
Manufacturer:
Name:
PNP Device ID: ACPI\IFX0101\4&3863886D&0
Service:
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
==== System Restore Points ===================
RP512: 2/04/2010 1:47:26 PM - System Checkpoint
RP513: 3/04/2010 3:19:10 PM - System Checkpoint
RP514: 5/04/2010 11:38:36 AM - System Checkpoint
RP515: 7/04/2010 12:31:06 PM - System Checkpoint
RP516: 8/04/2010 12:14:24 PM - Installed Windows XP Wdf01007.
RP517: 8/04/2010 12:40:42 PM - Installed Windows XP WIC.
RP518: 8/04/2010 12:48:42 PM - Installed %1 %2.
RP519: 8/04/2010 12:49:38 PM - Printer Driver Microsoft XPS Document Writer Installed
RP520: 8/04/2010 1:17:48 PM - Installed Nokia Map Loader.
RP521: 10/04/2010 12:03:52 AM - System Checkpoint
RP522: 11/04/2010 10:28:49 PM - System Checkpoint
RP523: 13/04/2010 9:20:25 PM - System Checkpoint
RP524: 17/04/2010 3:42:16 PM - System Checkpoint
RP525: 18/04/2010 8:58:18 PM - System Checkpoint
RP526: 22/04/2010 4:51:54 PM - System Checkpoint
RP527: 23/04/2010 5:07:59 PM - System Checkpoint
RP528: 24/04/2010 6:04:44 PM - System Checkpoint
RP529: 27/04/2010 4:11:00 PM - ComboFix created restore point
RP530: 28/04/2010 10:25:17 PM - System Checkpoint
RP531: 30/04/2010 8:57:23 PM - System Checkpoint
RP532: 1/05/2010 8:10:45 PM - Installed COMODO System - Cleaner
RP533: 1/05/2010 8:17:45 PM - Removed COMODO System - Cleaner
RP534: 1/05/2010 8:17:59 PM - [ErrorText_1715]
RP535: 1/05/2010 9:27:36 PM - Installed AVG 9.0
==== Installed Programs ======================
ABB Applications 1.0_1.0
Acrobat.com
Adobe Acrobat 6.0 Professional
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1
Agere Systems AC'97 Modem
Alinta GasLite GIS Default 1.0
Alinta UEmap 3.1_1.1
Alinta.HTML Help Config_1.0
Alinta.SAP Help Config_1.0
Alinta.ScreenSaver_1.0
Areva MiCOM S1 2.11
ATI Display Driver
Audsys
AutoCAD LT 2004
Autodesk Express Viewer
AVG 9.0
Cisco Systems VPN Client 5.0.02.0090
Cisco VPN Client - Alinta VPN.pcf
Cisco VPN Client - Modem and Broadband.pcf
COMODO System - Cleaner
Compatibility Pack for the 2007 Office system
Cyco AutoManager WorkFlow 6.1_2.0
Data Access Objects (DAO) 3.5
DIGSI 4 Devices
DIGSI 4.70
DivX Web Player
e-tax 2009
ERUNT 1.1j
ESRI MapObjects 2 Runtime 2.2
GasLite GIS
GE EnerVista UR Setup 4.8_1.0
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
IBM RecordNow! 7.22_1.1
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
InterVideo WinDvd 5.0
Irfan View 3.97
J2SE Runtime Environment 5.0
Java 2 Runtime Environment, SE v1.4.2_08
Java(TM) 6 Update 13
Java(TM) SE Runtime Environment 6 Update 1
LEGATO EmailXtender® 4.70 Client
LG PC Suite
LG USB Modem driver
Macromedia Flash Player 7.0-Shockwave Player 10.1_1.0
Malwarebytes' Anti-Malware
MetaFrame Presentation Server Client
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Visio Viewer 2003 (English)
Microsoft Organization Chart 2.0
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Modem Dialup
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 6.0 Parser
MYOB Accounting v17
MYOB ODBC Direct v7
Nokia Connectivity Cable Driver
Nokia Map Loader
Nokia Ovi Suite
Nokia Ovi Suite Software Updater
OfficeScan Client CE 5.58
Oracle 9i Client 9.2_1.0
Ovi Desktop Sync Engine
OviMPlatform
PC Connectivity Solution
PDFCreator
Protection Coordination Ultility 2.0
ProTesT 2.02
RealPlayer
SAP Front End 6.2_1.0
Schweitzer AcSELerator 2.4.11.6_1.0
Schweitzer SEL-5010 Relay Assistant 3.3.8_1.0
Schweitzer SEL-5601 2.3.7_1.0
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB921883)
Segoe UI
SMS Advanced Client
Spybot - Search & Destroy
System Update
TI Connect 1.6
Update for Windows Internet Explorer 7 (KB928089)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB911280)
Update for Windows XP (KB914882)
VC80CRTRedist - 8.0.50727.762
VideoLAN VLC media player 0.8.5
WebFldrs XP
Windows Communication Foundation
Windows Defender
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
WinZip
WinZip 10.0
Xerox AccXeS Client Tools 11.00.04
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
30/04/2010 6:58:57 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
3/05/2010 9:37:52 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:52 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:51 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:51 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:43 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
28/04/2010 9:15:20 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
27/04/2010 7:21:54 PM, error: NETLOGON [5719] - No Domain Controller is available for domain ALINTA due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
27/04/2010 7:21:43 PM, error: Dhcp [1002] - The IP address lease 0.0.0.0 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
27/04/2010 7:18:35 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00166F8C6A44. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
27/04/2010 4:35:56 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
27/04/2010 4:09:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
27/04/2010 3:58:48 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
27/04/2010 3:58:48 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
27/04/2010 3:58:43 PM, error: Dhcp [1002] - The IP address lease 192.168.0.100 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
26/04/2010 4:49:18 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u IntelIde mraid35x perc2 perc2hib ql1080 Ql10wnt ql12160 ql1240 ql1280 sisagp Sparrow symc810 symc8xx sym_hi sym_u3 TosIde ultra viaagp ViaIde
26/04/2010 2:49:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.100.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
26/04/2010 1:32:09 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.100.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
1/05/2010 8:16:50 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
1/05/2010 5:40:30 PM, error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Virus:Win32/Alureon.H&threatid=2147632576 User: NT AUTHORITY\SYSTEM Name: Virus:Win32/Alureon.H ID: 2147632576 Severity: Severe Category: Virus Path: Action: Clean Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.81.411.0, AS: 1.81.411.0 Engine Version: 1.1.5703.0
1/05/2010 4:19:57 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\advapi32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.2180.
1/05/2010 2:25:32 PM, error: Dhcp [1002] - The IP address lease 192.168.0.101 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================
My computer has been getting infected by one virus after another. I believe it is still infected even though I've tried a number of programs. I have run (and still have some programs installed)
- Spybot
- AVG
- Malwarebytes' Anti-Malware
- Microsoft Security
- Comodo Cleaner
- Combofix
I have read that you do not recommend using cleaners and fix tools - I suppose I'm lucky that my computer didn't turn into a brick. I used combofix to remove the 'google redirect virus'. It detected rookit activity and appears to have fixed that problem.
I have also had the 'XP Antivirus 2010' virus, which was removed. My anti-virus also picked up win32/Alureon.H a day or so later.
THANKS for your help!
DDS logs:
DDS (Ver_10-03-17.01) - NTFSx86
Run by rhong at 22:15:46.43 on Mon 03/05/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.2.1252.61.1033.18.1023.411 [GMT 10:00]
AV: Microsoft Security Essentials *On-access scanning enabled* (Outdated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Siemens\Digsi4\Common\sws\almsrv\almsrvx.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\program files\lenovo\system update\suservice.exe
C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe
C:\Program Files\Common Files\Lenovo\Scheduler\tvtsched.exe
C:\Program Files\Trend Micro\OfficeScan Client\ofcdog.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Nokia\Nokia Ovi Suite\NokiaOviSuite.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\Nokia\NoA\nokiaaserver.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\PROGRA~1\COMMON~1\Nokia\MPLATF~1\NOKIAM~1.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\rhong\Desktop\dds.com
============== Pseudo HJT Report ===============
uStart Page = https://my.monash.edu.au/
uInternet Settings,ProxyServer = 10.84.243.71:8080
uInternet Settings,ProxyOverride = hxxp://amfm.ue.com.au;10.250.1.103;http://plp.ue.com.au;https://plp.ue.com.au;http://j2eprd01.ue.com.au;http://vtalpwinf01.alinta.net.int;http://vtalpwctx10;http://vtalpwctx60;<local>
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 6.0\acrobat\AcroIEFavClient.dll
uRun: [NokiaOviSuite2] c:\program files\nokia\nokia ovi suite\NokiaOviSuite.exe -tray
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [WatchDog] c:\program files\intervideo\dvd check\DVDCheck.exe
mRun: [OfficeScanNT Monitor] "c:\program files\trend micro\officescan client\PccNTMon.exe" -HideWindow
mRun: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
mRun: [SqlEng] "c:\program files\sqlany50\win32\rtdsk50.exe" -n protest.db"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [TVT Scheduler Proxy] c:\program files\common files\lenovo\scheduler\scheduler_proxy.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\rhong\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dvdche~1.lnk - c:\program files\intervideo\dvd check\DVDCheck.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\vpncli~1.lnk - c:\windows\installer\{871df2be-41d2-4334-ac33-839af16fc8fe}\Icon3E5562ED7.ico
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoStartMenuMyMusic = 1 (0x1)
uPolicies-explorer: ForceStartMenuLogOff = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
uPolicies-explorer: DisablePersonalDirChange = 1 (0x1)
uPolicies-system: ProfileQuotaMessage = Alinta Helpdesk: You have exceeded your profile storage space. Before you can log off, you need to move some items from your profile to your "My Documents" folder or your computer's "D:\Transient" folder.
uPolicies-system: MaxProfileSize = 30000 (0x7530)
uPolicies-system: WarnUserTimeout = 15 (0xf)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab
DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
DPF: {5D6F45B3-9043-443D-A792-115447494D24} - hxxp://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6087.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269862591171
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269862795015
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://messenger.zone.msn.com/EN-US/a-LUXR/mjolauncher.cab
DPF: {89FD2ED9-0000-0000-0000-000000000000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - hxxp://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://zone.msn.com/bingame/zpagames/zpa_txhe.cab53083.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab53083.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab53852.cab
DPF: {DEA03428-0000-0000-0000-000000000000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} - hxxp://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: saphtmlp - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Handler: sapr3 - {D1F8BD1E-7967-11D2-B43A-006094B9EADB} - c:\program files\sap\frontend\controls\SAPHTMLP.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-5-1 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-5-1 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-1 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-1 29512]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-1 242896]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]
R2 almservice;Automation License Server;c:\siemens\digsi4\common\sws\almsrv\almsrvx.exe [2006-9-16 573502]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-1 308064]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-5-1 2325816]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-5-1 5888008]
R2 TmFilter;Trend Micro Filter;c:\program files\trend micro\officescan client\tmxpflt.sys [2005-2-18 197648]
R2 TmPreFilter;Trend Micro PreFilter;c:\program files\trend micro\officescan client\tmpreflt.sys [2005-2-18 31248]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-5-1 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-5-1 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-5-1 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-5-1 26120]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2005-10-24 80384]
S0 CFRMD;CFRMD;c:\windows\system32\drivers\cfrmd.sys --> c:\windows\system32\drivers\CFRMD.sys [?]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-5-1 30104]
S3 TPM12;NSC Integrated Trusted Platform Module 1.2;c:\windows\system32\drivers\nsctpm12.sys [2006-2-24 13056]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2005-1-26 280344]
============== File Associations ===============
.scr=AutoCADLTScriptFile
=============== Created Last 30 ================
2010-05-03 11:30:24 0 d-----w- c:\docume~1\rhong\applic~1\AVG9
2010-05-01 11:33:54 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-01 11:33:53 25096 ----a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-01 11:33:52 52872 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-01 11:33:46 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-01 11:33:37 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-01 11:33:19 0 d-----w- c:\windows\system32\drivers\Avg
2010-05-01 11:30:14 50968 ----a-w- c:\windows\system32\avgfwdx.dll
2010-05-01 11:30:14 30104 ----a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-05-01 11:27:37 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-05-01 11:25:04 0 d-----w- c:\program files\AVG
2010-05-01 10:32:56 0 d-----w- c:\docume~1\rhong\applic~1\ComodoGroup
2010-05-01 10:24:59 0 d-----w- c:\documents and settings\rhong\Application DataComodoGroup
2010-05-01 10:10:46 0 d-----w- c:\program files\COMODO
2010-04-27 06:24:15 0 d-sha-r- C:\cmdcons
2010-04-27 06:10:19 77312 ----a-w- c:\windows\MBR.exe
2010-04-27 06:10:15 98816 ----a-w- c:\windows\sed.exe
2010-04-27 06:10:15 261632 ----a-w- c:\windows\PEV.exe
2010-04-27 06:10:15 161792 ----a-w- c:\windows\SWREG.exe
2010-04-27 06:09:49 0 d-----w- C:\ComboFix
2010-04-26 07:05:10 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-04-26 07:05:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-04-24 10:13:39 0 d-----w- c:\docume~1\rhong\applic~1\Malwarebytes
2010-04-24 10:12:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-24 10:12:38 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-24 10:12:36 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-24 10:12:35 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-08 02:51:04 0 d-----w- c:\windows\system32\XPSViewer
2010-04-08 02:48:42 14048 ------w- c:\windows\system32\spmsg2.dll
2010-04-08 02:28:23 0 d-----w- c:\docume~1\alluse~1\applic~1\Nokia
2010-04-08 02:20:32 0 d-----w- c:\docume~1\rhong\applic~1\Nokia Ovi Suite
2010-04-08 02:14:59 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2010-04-08 02:14:59 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2010-04-08 02:14:44 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2010-04-08 02:14:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-04-08 02:14:24 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-04-08 01:55:10 0 d-----w- c:\program files\common files\Nokia
2010-04-08 01:50:31 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-04-08 01:49:14 0 d-----w- c:\program files\PC Connectivity Solution
2010-04-08 01:48:38 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2010-04-08 01:48:38 7936 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2010-04-08 01:48:36 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2010-04-08 01:48:32 18048 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2010-04-08 01:48:31 660480 ----a-w- c:\windows\system32\nmwcdcocls.dll
2010-04-08 01:48:31 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2010-04-08 01:48:01 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2010-04-07 14:41:39 0 d-----w- c:\program files\MSXML 6.0
2010-04-07 14:37:53 0 d-----w- c:\program files\Nokia
2010-04-07 14:37:53 0 d-----w- c:\docume~1\alluse~1\applic~1\OviInstallerCache
2010-04-05 08:32:28 3248 ----a-w- c:\windows\system32\wbem\Outlook_01cad49a864f46f8.mof
==================== Find3M ====================
2010-02-24 00:16:06 181632 ------w- c:\windows\system32\MpSigStub.exe
============= FINISH: 22:17:18.31 ===============
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 14/07/2006 3:43:25 AM
System Uptime: 5/03/2010 9:40:29 PM (1417 hours ago)
Motherboard: Hewlett-Packard | | 0934
Processor: Intel(R) Pentium(R) M processor 1.73GHz | U10 | 1729/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 20 GiB total, 2.411 GiB free.
D: is FIXED (NTFS) - 17 GiB total, 16.913 GiB free.
E: is CDROM ()
M: is NetworkDisk (*NT5CSC) - 20 GiB total, 2.411 GiB free.
==== Disabled Device Manager Items =============
Class GUID: {6BDD1FC5-810F-11D0-BEC7-08002BE2092F}
Description: SMC IrCC - Fast Infrared Port
Device ID: ACPI\SMCF010\5&16574359&0
Manufacturer: SMC
Name: SMC IrCC - Fast Infrared Port
PNP Device ID: ACPI\SMCF010\5&16574359&0
Service: SMCIRDA
Class GUID:
Description:
Device ID: ACPI\IFX0101\4&3863886D&0
Manufacturer:
Name:
PNP Device ID: ACPI\IFX0101\4&3863886D&0
Service:
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Cisco Systems VPN Adapter
Device ID: ROOT\NET\0000
Manufacturer: Cisco Systems
Name: Cisco Systems VPN Adapter
PNP Device ID: ROOT\NET\0000
Service: CVirtA
==== System Restore Points ===================
RP512: 2/04/2010 1:47:26 PM - System Checkpoint
RP513: 3/04/2010 3:19:10 PM - System Checkpoint
RP514: 5/04/2010 11:38:36 AM - System Checkpoint
RP515: 7/04/2010 12:31:06 PM - System Checkpoint
RP516: 8/04/2010 12:14:24 PM - Installed Windows XP Wdf01007.
RP517: 8/04/2010 12:40:42 PM - Installed Windows XP WIC.
RP518: 8/04/2010 12:48:42 PM - Installed %1 %2.
RP519: 8/04/2010 12:49:38 PM - Printer Driver Microsoft XPS Document Writer Installed
RP520: 8/04/2010 1:17:48 PM - Installed Nokia Map Loader.
RP521: 10/04/2010 12:03:52 AM - System Checkpoint
RP522: 11/04/2010 10:28:49 PM - System Checkpoint
RP523: 13/04/2010 9:20:25 PM - System Checkpoint
RP524: 17/04/2010 3:42:16 PM - System Checkpoint
RP525: 18/04/2010 8:58:18 PM - System Checkpoint
RP526: 22/04/2010 4:51:54 PM - System Checkpoint
RP527: 23/04/2010 5:07:59 PM - System Checkpoint
RP528: 24/04/2010 6:04:44 PM - System Checkpoint
RP529: 27/04/2010 4:11:00 PM - ComboFix created restore point
RP530: 28/04/2010 10:25:17 PM - System Checkpoint
RP531: 30/04/2010 8:57:23 PM - System Checkpoint
RP532: 1/05/2010 8:10:45 PM - Installed COMODO System - Cleaner
RP533: 1/05/2010 8:17:45 PM - Removed COMODO System - Cleaner
RP534: 1/05/2010 8:17:59 PM - [ErrorText_1715]
RP535: 1/05/2010 9:27:36 PM - Installed AVG 9.0
==== Installed Programs ======================
ABB Applications 1.0_1.0
Acrobat.com
Adobe Acrobat 6.0 Professional
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.1
Agere Systems AC'97 Modem
Alinta GasLite GIS Default 1.0
Alinta UEmap 3.1_1.1
Alinta.HTML Help Config_1.0
Alinta.SAP Help Config_1.0
Alinta.ScreenSaver_1.0
Areva MiCOM S1 2.11
ATI Display Driver
Audsys
AutoCAD LT 2004
Autodesk Express Viewer
AVG 9.0
Cisco Systems VPN Client 5.0.02.0090
Cisco VPN Client - Alinta VPN.pcf
Cisco VPN Client - Modem and Broadband.pcf
COMODO System - Cleaner
Compatibility Pack for the 2007 Office system
Cyco AutoManager WorkFlow 6.1_2.0
Data Access Objects (DAO) 3.5
DIGSI 4 Devices
DIGSI 4.70
DivX Web Player
e-tax 2009
ERUNT 1.1j
ESRI MapObjects 2 Runtime 2.2
GasLite GIS
GE EnerVista UR Setup 4.8_1.0
High Definition Audio Driver Package - KB888111
Hotfix for Windows XP (KB893357)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
IBM RecordNow! 7.22_1.1
Intel(R) Graphics Media Accelerator Driver
Intel(R) PRO Network Connections Drivers
InterVideo WinDvd 5.0
Irfan View 3.97
J2SE Runtime Environment 5.0
Java 2 Runtime Environment, SE v1.4.2_08
Java(TM) 6 Update 13
Java(TM) SE Runtime Environment 6 Update 1
LEGATO EmailXtender® 4.70 Client
LG PC Suite
LG USB Modem driver
Macromedia Flash Player 7.0-Shockwave Player 10.1_1.0
Malwarebytes' Anti-Malware
MetaFrame Presentation Server Client
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Antimalware
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft Office Visio Viewer 2003 (English)
Microsoft Organization Chart 2.0
Microsoft Security Essentials
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Modem Dialup
MSVC80_x86_v2
MSVC90_x86
MSVCRT
MSXML 6.0 Parser
MYOB Accounting v17
MYOB ODBC Direct v7
Nokia Connectivity Cable Driver
Nokia Map Loader
Nokia Ovi Suite
Nokia Ovi Suite Software Updater
OfficeScan Client CE 5.58
Oracle 9i Client 9.2_1.0
Ovi Desktop Sync Engine
OviMPlatform
PC Connectivity Solution
PDFCreator
Protection Coordination Ultility 2.0
ProTesT 2.02
RealPlayer
SAP Front End 6.2_1.0
Schweitzer AcSELerator 2.4.11.6_1.0
Schweitzer SEL-5010 Relay Assistant 3.3.8_1.0
Schweitzer SEL-5601 2.3.7_1.0
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB921883)
Segoe UI
SMS Advanced Client
Spybot - Search & Destroy
System Update
TI Connect 1.6
Update for Windows Internet Explorer 7 (KB928089)
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB911280)
Update for Windows XP (KB914882)
VC80CRTRedist - 8.0.50727.762
VideoLAN VLC media player 0.8.5
WebFldrs XP
Windows Communication Foundation
Windows Defender
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Sign-in Assistant
Windows Live Upload Tool
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
WinRAR archiver
WinZip
WinZip 10.0
Xerox AccXeS Client Tools 11.00.04
XML Paper Specification Shared Components Pack 1.0
==== Event Viewer Messages From Past Week ========
30/04/2010 6:58:57 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
3/05/2010 9:37:52 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:52 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:51 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:51 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Malware Protection Center Update Stage: Search Source Path: http://go.microsoft.com/fwlink/?Lin...1.0&prod=BCF43643-A118-4432-AEDE-D861FCBCFCDE Signature Type: AntiSpyware Update Type: Full User: NT AUTHORITY\NETWORK SERVICE Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80072ee7 Error description: The server name or address could not be resolved
3/05/2010 9:37:43 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
28/04/2010 9:15:20 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
27/04/2010 7:21:54 PM, error: NETLOGON [5719] - No Domain Controller is available for domain ALINTA due to the following: There are currently no logon servers available to service the logon request. . Make sure that the computer is connected to the network and try again. If the problem persists, please contact your domain administrator.
27/04/2010 7:21:43 PM, error: Dhcp [1002] - The IP address lease 0.0.0.0 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
27/04/2010 7:18:35 PM, error: Dhcp [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 00166F8C6A44. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.
27/04/2010 4:35:56 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired.
27/04/2010 4:09:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
27/04/2010 3:58:48 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
27/04/2010 3:58:48 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.
27/04/2010 3:58:43 PM, error: Dhcp [1002] - The IP address lease 192.168.0.100 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
26/04/2010 4:49:18 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: abp480n5 adpu160m agp440 agpCPQ Aha154x aic78u2 aic78xx AliIde alim1541 amdagp amsint asc asc3350p asc3550 cbidf cd20xrnt CmdIde Cpqarray dac2w2k dac960nt dpti2o hpn i2omp ini910u IntelIde mraid35x perc2 perc2hib ql1080 Ql10wnt ql12160 ql1240 ql1280 sisagp Sparrow symc810 symc8xx sym_hi sym_u3 TosIde ultra viaagp ViaIde
26/04/2010 2:49:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.100.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
26/04/2010 1:32:09 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.100.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
1/05/2010 8:16:50 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.81.411.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.5703.0 Error code: 0x80248014 Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
1/05/2010 5:40:30 PM, error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Virus:Win32/Alureon.H&threatid=2147632576 User: NT AUTHORITY\SYSTEM Name: Virus:Win32/Alureon.H ID: 2147632576 Severity: Severe Category: Virus Path: Action: Clean Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.81.411.0, AS: 1.81.411.0 Engine Version: 1.1.5703.0
1/05/2010 4:19:57 PM, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\windows\system32\advapi32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.2180.
1/05/2010 2:25:32 PM, error: Dhcp [1002] - The IP address lease 192.168.0.101 for the Network Card with network address 00166F8C6A44 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).
==== End Of File ===========================